CVE-2026-72075

high

Description

In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix race condition in reset_device sysfs callback The ims_pcu_reset_device() sysfs callback calls ims_pcu_execute_command() without acquiring pcu->cmd_mutex. This can lead to data races and corruption of the shared command buffer if triggered concurrently with other commands. Acquire pcu->cmd_mutex before calling ims_pcu_execute_command().

References

https://git.kernel.org/stable/c/f516cba88bf952d847e5c96d0e87f17eaae7ee6f

https://git.kernel.org/stable/c/54c2237fc69541c75fe4cd321622ebb8ecc3587f

https://git.kernel.org/stable/c/411b8c4b274737c3bf08e1e025801161603cfffc

https://git.kernel.org/stable/c/129187ec3f868829f61f6f07381ca72fe642d0b7

https://git.kernel.org/stable/c/0fb84b1a3cdc74c453abc5f961c7d318c267ea4c

https://git.kernel.org/stable/c/025955847e1500ced4719ac178beff6a3b2f0e3c

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-15

Risk Information

CVSS v2

Base Score: 6.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00215